LWN.net Logo

munin: privilege escalation

Package(s):munin CVE #(s):CVE-2012-3512
Created:September 26, 2012 Updated:November 5, 2012
Description: From the Red Hat bugzilla:

Currently, plugins which run as root mix their state files in the same directory as non-root plugins. The state directory is owned by munin:munin and is group-writable. Because of these facts, it is possible for an attacker who operates as user munin to cause a root-run plugin to run arbitrary code as root.

Alerts:
Fedora FEDORA-2012-13683 2012-09-26
Fedora FEDORA-2012-13649 2012-09-26
Ubuntu USN-1622-1 2012-11-05
Mageia MGASA-2012-0358 2012-12-11
Mandriva MDVSA-2013:105 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds